CyberRota Analysis
AI-GeneratedIBM MQ versions 9.1 through 10.0 are vulnerable to XML external entity injection in the processing of MQRFH2 headers, which could allow authenticated attackers to access sensitive information or trigger a denial of service. Organizations using these versions of IBM MQ should prioritize patching to mitigate the risk of data exposure and service disruption. This vulnerability is particularly critical for environments handling sensitive data or requiring high availability.
Original NVD Description
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Classes for Java could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to XML external entity injection in MQRFH2 header processing.